Attack surface
In one sentence
The full set of ways an attacker could try to get in: every account, device, app, and internet-facing service.
Your attack surface is the sum of all entry points exposed to potential attackers. Reducing it (closing unused services, retiring old systems, limiting internet exposure) is a core defensive goal.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
MFA & identity
Is MFA required for remote access (VPN, remote desktop) and administrator accounts?
Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.
If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.
Patching & vulnerabilities
How are security updates applied to your systems and software?
Why carriers ask: Unpatched, internet-facing software is now a leading initial-access vector. Applications ask about patch cadence and end-of-life systems specifically.
If the answer is no: Have whoever manages IT produce a list of what's patched automatically vs. manually. That list becomes your patch-management policy's appendix.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.